Dependency-Track
DependencyTrack
Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain
CycloneDX BOM Standard
CycloneDX
CycloneDX is a modern standard for the software supply chain. SBOM, SaaSBOM, CBOM, OBOM, VEX, and more. CycloneDX is a OWASP project ratified as ECMA-424
Philippe Ombredanne
pombredanne
Passionate FOSS hacker on a mission: healthy & safe software supply chains with FOSS tools, open data & standards @aboutcode-org @package-url @clearlydefine
@aboutcode-org @package-url @clearlydefined @nexB Earth
Sebastian Schuberth
sschuberth
A Kotlin enthusiast who's enjoying to work with and on Open Source Software.
CTO of @doubleopen-project Berlin, Germany
Steve Springett
stevespringett
I build stuff, I break stuff, I develop stuff to protect stuff.
Creator of @DependencyTrack. Chair of @CycloneDX and @Ecma-TC54. Core team of @package-url
@ServiceNow Chicago
Package-URL
package-url
A minimal specification and implementation of PURL (Package URL) and VERS (Version Range Specifier)